Hackers exploit BGP hijacking in supply chain attack targeting Softaculous users

Attackers exploited weaknesses in Hetzner's routing security and TLS certificate validation to push malware as software updates

edit
By LineZotpaper
Published
Read Time2 min
Hackers have carried out a supply chain attack that compromised real networks by hijacking Internet address space belonging to Softaculous, a UAE-based maker of web software and virtualization management platforms, exploiting flaws in hosting provider Hetzner Online's routing security and the TLS certificate issuance process.

In a well-coordinated operation, unknown attackers performed a Border Gateway Protocol (BGP) hijacking to gain control over IP addresses assigned to Softaculous, the developer of Virtualizor and a platform for installing and managing web software. The company had used those IP addresses to issue software updates and host its client and billing site. Once in control of the hijacked space, the attackers pushed malware disguised as legitimate updates to unsuspecting users.

The security breach leveraged weaknesses in Hetzner Online's routing security setup and the process for obtaining valid TLS certificates, according to a report by Ars Technica. The attack represents an unusual convergence of routing protocol exploitation and supply chain compromise, allowing the threat actors to infect networks at scale without the need for more conventional intrusion methods.

As of the report's publication, the full extent of the compromise and the identity of the attackers remain unknown. The incident highlights ongoing vulnerabilities in the Internet's core routing infrastructure, where BGP relies largely on trust rather than built-in security mechanisms.

§

Analysis

Why This Matters

  • The attack demonstrates a sophisticated, real-world use of BGP hijacking to conduct a supply chain attack, potentially affecting hosting providers, data centers, and large infrastructure companies that rely on Softaculous or Virtualizor.
  • It underscores how weaknesses in routing security and TLS certificate validation can be combined to compromise software update mechanisms, a high-value vector for malware distribution.
  • The incident may prompt renewed scrutiny of BGP security standards such as RPKI and Resource Public Key Infrastructure adoption, as well as cloud management software update practices.

Background

Border Gateway Protocol is the fundamental routing protocol that directs traffic across the Internet. It has long been known to be vulnerable to hijacking because it trusts announcements from other networks without strong verification. While technologies like RPKI exist to help validate route announcements, adoption remains incomplete. BGP hijacks have historically been used for spam, phishing, or cryptocurrency theft, but using them to push malware through a software supply chain is an escalation.

Key Perspectives

Network operators and security researchers: See this as a wake-up call that BGP hijacking can enable sophisticated, multi-stage attacks reaching beyond simple traffic interception. They emphasize the need for universal adoption of route origin validation. Hetzner Online and Softaculous: As the victims, they face questions about their security configurations and the adequacy of existing protections against route hijacking and TLS certificate misissuance. Both companies may face pressure to implement stronger controls. Critics/Skeptics: May point out that such attacks, while alarming, require careful coordination and may not be scalable beyond specific targets. They may also question whether this incident will drive meaningful changes in routing security practice given the slow pace of adoption.

What to Watch

  • Whether Hetzner Online or Softaculous release detailed post-incident reports or security advisories with mitigation steps.
  • Any evidence that other BGP hijacks are being used for similar supply chain compromises, suggesting a broader threat campaign.
  • Movement on regulatory or industry standards for BGP security, such as updated requirements from cloud providers or certification authorities.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.